BlackTree Security · Infrastructure · Automation · AI

Australia’s Critical-Infrastructure Regulator Wants More Than a Signed Risk Report

Covered responsible entities under Australia’s critical-infrastructure regime must file their 2025-26 risk-management reports by 28 September 2026. At the same time, the Critical Infrastructure Security Centre (CISC) says it will escalate serious or persistent non-compliance during the 2026-27 cycle. The practical question for boards is whether the controls behind their annual statement will withstand scrutiny after the form has been filed.

The CISC’s regulatory philosophy says voluntary compliance comes first, followed by proportionate escalation where necessary. Its SOCI overview places the change in the 2026-27 cycle. This is an enforcement approach under the existing Security of Critical Infrastructure Act 2018, not a new penalty or a claim that every late report will attract a fine. The regulator has not announced a specific enforcement action in the material reviewed for this article.

Who actually has to file?

The Act ties the return to a responsible entity and a covered asset with an applicable risk programme during all or part of the financial year. The current CIRMP Rules specify 13 asset classes, including certain broadcasting, DNS, data-processing, electricity, energy-market, gas, hospital, food, freight, fuel, payment-system and water assets. A sector label alone does not settle whether an asset meets the statutory definition; applicable transitions and declarations also matter.

Telecommunications has its own risk-management rules. Under the 2025 telecommunications rules, the relevant assets include those owned or operated by carriers and specified carriage-service-provider assets. The latter test includes at least 20,000 active carriage services, or services supplied to a qualifying Commonwealth entity. CISC’s telecommunications guidance says the first annual report under that regime covers 2025-26 and is due by 28 September 2026. The threshold is about the regulated asset and service, not a general employee-count exemption. Smaller providers may still have other SOCI obligations, as CISC explains in its telecommunications town hall.

The Act applies within and outside Australia. An overseas headquarters therefore does not, by itself, decide whether an entity responsible for a covered Australian asset is in scope. Applicability still depends on the asset, the responsible entity and the rules that switch on the relevant obligation.

What the board is approving

Section 30AG sets a 90-day window after the Australian financial year ends. CISC gives 28 September 2026 as the 2025-26 due date. The checked official guidance does not specify a public filing hour or timezone, so the date should not be read as a promise of extra time.

The approved reporting form asks whether the programme was up to date at year-end and, where relevant, what significant hazards occurred and how effectively the programme mitigated them. It also covers resulting programme changes and regulatory directions. Telecommunications returns add information about notified service changes, advised risks and responses. Where an entity has a board, council or other governing body, that body must approve the report.

The report goes to the relevant Commonwealth regulator for an asset, or otherwise to the Home Affairs Secretary. The CIRMP Rules name the Reserve Bank of Australia for the specified payment-system class; CISC’s telecommunications guidance identifies CISC for telecommunications. The full programme need not accompany the return, but the regulator may request it in an audit. A signature does not prove that the programme is current or followed in practice.

There is one timing trap. The enhanced CIRMP Rules took effect in June 2026 for specified assets, but their individual measures have transition periods. At its 25 June 2026 town hall, CISC said operators do not need to report on the enhanced measures in the 2025-26 attestation and will address them in the next reporting year. That does not defer the baseline programme or this year’s report. It means teams should separate the 2025-26 statement from their forward implementation plan.

The enforcement change, without the alarmism

The 2026 independent review urged a move from document-centred supervision towards enforcement of risk management. CISC’s response lists notices, directions, undertakings, infringement notices and prosecution among possible tools. Its examples for escalation include serious or persistent non-compliance and a significant unmitigated national-security threat. Those are examples of regulatory discretion, not automatic outcomes.

Those powers already sit in law. The Act specifies a 150 penalty-unit civil penalty for the annual-report duty and 200 penalty units for each duty to adopt, comply with, review and update the programme. These are amounts in statutory units, not fines CISC has imposed in this case. Section 30AG also limits use of the annual report as evidence against the entity in civil penalty proceedings under the Act. CISC can still review the underlying programme in a compliance audit.

Based on the statutory duties and regulator guidance, BlackTree recommends this evidence check for covered operators:

  1. Confirm the responsible entity, asset class, applicable rules and reporting recipient, including the separate telecommunications regime where relevant.
  2. Compare the board statement with hazard and incident records, control tests, supplier access and any directions received. Record discrepancies before approval.
  3. Keep proof of approval and submission, and retain the programme and supporting control evidence for a possible review.
  4. Track each applicable enhanced-rule measure and transition date separately from the 2025-26 attestation.
  5. If a required report was missed, contact CISC promptly with the facts and a board-backed remediation plan. CISC’s industry town hall encourages engagement, but contact does not automatically extend the deadline.

BlackTree’s earlier SOCI explainer describes incident reporting and last-resort government intervention. The current development concerns the ordinary annual assurance cycle: whether an entity’s claims about resilience match the controls protecting the asset before a crisis begins.

This article is general editorial information, not advice on whether a particular organisation or asset is legally in scope.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *